Details

Updated xorg-x11 packages that fix several security issues are now
available for Red Hat Enterprise Linux 4.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

The xorg-x11 packages contain X.Org, an open source implementation of the XWindow System. It provides the basic low-level functionality thatfull-fledged graphical user interfaces are designed upon.

An input validation flaw was discovered in X.org's Security and Recordextensions. A malicious authorized client could exploit this issue to causea denial of service (crash) or, potentially, execute arbitrary code withroot privileges on the X.Org server. (CVE-2008-1377)

An input validation flaw was discovered in X.org's MIT-SHM extension. Aclient connected to the X.org server could read arbitrary server memory.This could result in the sensitive data of other users of the X.org serverbeing disclosed. (CVE-2008-1379)

Users of xorg-x11 should upgrade to these updated packages, which containbackported patches to resolve these issues.

Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.